News

Fortinet Post-Quantum Cryptography: From Awareness to Action 2026

News | 28.07.2026

Quantum computing is no longer a distant theoretical concern. Adversaries are already collecting encrypted data today to decrypt it once cryptographically relevant quantum computers arrive, and enterprise security leaders must act now to protect long-lived sensitive information.

The transition to post-quantum cryptography (PQC) represents one of the most significant shifts in enterprise security architecture in decades. Fortinet is guiding organizations through this journey, translating industry awareness into practical, phased action plans that align with NIST standards and real-world operational constraints.

What was announced

Fortinet published a strategic outlook on helping organizations move from PQC awareness to structured action. The guidance focuses on how enterprises can prepare cryptographic inventories, prioritize high-value assets, and align migration roadmaps with the finalized NIST PQC algorithms, including ML-KEM, ML-DSA, and SLH-DSA.

The core message is that quantum readiness is not a single project but a multi-year program requiring cryptographic agility, vendor coordination, and risk-based prioritization. Fortinet is embedding PQC-ready capabilities across its Security Fabric, enabling customers to test and adopt quantum-safe algorithms without disruptive re-architecture.

Why this matters

For CIOs, CISOs, and IT procurement leaders, the harvest-now-decrypt-later threat model changes the risk calculus immediately. Data encrypted today with classical algorithms such as RSA-2048 or ECC could be decrypted retroactively once a cryptographically relevant quantum computer becomes available. Sensitive records with a shelf life of 10 to 25 years, including financial records, healthcare data, government archives, and intellectual property, are already exposed.

Delaying PQC planning increases technical debt. Organizations that lack cryptographic inventories will struggle to identify where vulnerable algorithms are embedded across VPNs, TLS sessions, code signing, PKI, IoT firmware, and hardware security modules. Early movers gain crypto-agility, reduce future migration costs, and meet emerging regulatory expectations from bodies such as the U.S. National Security Memorandum NSM-10 and evolving EU guidance.

Quantum readiness is a governance decision as much as a cryptographic one, and it requires cross-functional alignment starting today

Fortinet security leadership perspective

Technical details

  • NIST PQC algorithms: Support for ML-KEM (formerly Kyber) for key encapsulation and ML-DSA (formerly Dilithium) for digital signatures
  • Hybrid modes: Combining classical and post-quantum algorithms during transition to preserve backward compatibility
  • Crypto-agility: Modular cryptographic architecture allowing algorithm updates without re-engineering applications
  • Inventory approach: Systematic discovery of cryptographic assets across VPNs, TLS, PKI, code signing, and embedded systems
  • Risk prioritization: Focus on long-lived sensitive data and externally exposed cryptographic endpoints first
  • Fabric integration: PQC readiness embedded across FortiGate, FortiOS, and secure networking components

Softprom and Fortinet

Softprom is the official distributor of Fortinet. Our team supports enterprise customers with pre-sales consulting, licensing, deployment services, and technical enablement for the full Fortinet Security Fabric, including quantum-readiness planning.

This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.